Component Object Model

T1559.001

Sub-technique of T1559 Inter-Process Communication.View on attack.mitre.org

About this technique

Adversaries may use the Windows Component Object Model (COM) for local code execution. COM is an inter-process communication (IPC) component of the native Windows application programming interface (API) that enables interaction between software objects, or executable code that implements one or more interfaces. Through COM, a client object can call methods of server objects, which are typically binary Dynamic Link Libraries (DLL) or executables (EXE). Remote COM execution is facilitated by Remote Services such as Distributed Component Object Model (DCOM).

Various COM interfaces are exposed that can be abused to invoke arbitrary execution via a variety of programming languages such as C, C++, Java, and Visual Basic. Specific COM objects also exist to directly perform functions beyond code execution, such as creating a Scheduled Task/Job, fileless download/execution, and other adversary behaviors related to privilege escalation and persistence.

Detection rules4

Rules on DetectionCode tagged with T1559.001.

Sigma3

RuleLevelLog source
CMSTP Execution Process Accesshighwindows / process_access
DNS Query Request By Regsvr32.EXEmediumwindows / dns_query
Network Connection Initiated By Regsvr32.EXEmediumwindows / network_connection

Splunk1

RuleTypeRiskData source
Process Writing DynamicWrapperXHuntingNULLSysmon EventID 11

Groups4

Software18

Campaigns0

None recorded.

Procedure examples22

Groups4

Used byProcedure example
GroupGamaredon Group

Gamaredon Group malware can insert malicious macros into documents using a Microsoft.Office.Interop object.

GroupKimsuky

Kimsuky has leveraged Component Object Model (COM) to create scheduled tasks to include using naming conventions that mimic legitimate applications. Kimsuky has leveraged obfuscation VBScript to form a string in `WScript.Shell` which has downloaded a malicious payload to the victim environment.

GroupMedusa Group

Medusa Group has leveraged Component Object Model (COM) to bypass UAC.

GroupMuddyWater

MuddyWater has used malware that has the capability to execute malicious code via COM, DCOM, and Outlook.

Software18

Used byProcedure example
MalwareBumblebee

Bumblebee can use a COM object to execute queries to gather system information.

MalwareCLAIMLOADER

CLAIMLOADER has leveraged Component Object Model (COM) objects to create a scheduled task using `ITaskService` interface.

MalwareDarkTortilla

DarkTortilla has used the `WshShortcut` COM object to create a .lnk shortcut file in the Windows startup folder.

MalwareFunnyDream

FunnyDream can use com objects identified with `CLSID_ShellLink`(`IShellLink` and `IPersistFile`) and `WScript.Shell`(`RegWrite` method) to enable persistence mechanisms.

MalwareGelsemium

Gelsemium can use the `IARPUinstallerStringLauncher` COM interface are part of its UAC bypass process.

MalwareHermeticWizard

HermeticWizard can execute files on remote machines using DCOM.

MalwareInvisiMole

InvisiMole can use the ITaskService, ITaskDefinition and ITaskSettings COM interfaces to schedule a task.

MalwareLatrodectus

Latrodectus can use the Windows Component Object Model (COM) to set scheduled tasks.

View all 18 software examples

References3

  1. Fireeye Hunting COM June 2019 Open source
    Hamilton, C. (2019, June 4). Hunting COM Objects. Retrieved June 10, 2019.
  2. Microsoft COM Open source
    Microsoft. (n.d.). Component Object Model (COM). Retrieved November 22, 2017.
  3. ProjectZero File Write EoP Apr 2018 Open source
    Forshaw, J. (2018, April 18). Windows Exploitation Tricks: Exploiting Arbitrary File Writes for Local Elevation of Privilege. Retrieved May 3, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.